Tamper Detection
A latch that survives the power cycle
Active mesh and environmental monitors feed a persistent suspect-tamper state. Keys zeroise; return to service needs authenticated remediation.
Design targets · not measured silicon results
- Trust boundary
- Supporting logic
- Signed data in flight
Detection a reset can clear is not detection
Probing, glitching and fault injection do not open a lid. If the tamper flag is volatile or rewriteable, removing power erases the event and the device returns to service clean.
- Measured epoch
- Flagged for re-measure
- Light = the digest being extended
Sense the surface, then latch the consequence
A driven mesh plus supply, clock and temperature monitors catch physical attack paths. On fire, state latches in the trust domain, keys zeroise, and only authenticated remediation restores service.
What follows from the diagram
-
Active mesh
Cut, short or reroute changes a measured response
-
Environmental monitors
Glitch and fault injection appear as out-of-envelope events
-
Persistent state
Tamper survives power loss in the trust domain
-
Zeroise + remediate
Keys die on detection; reboot alone cannot clear it
Reviewing this mechanism?
The specification can still change. That stops being true after tape-out.